Security Advisory

CVE-2025-5526

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-06-27 06:00:11
Last updated 2025-07-01 19:19:08
Assigner WPScan
State PUBLISHED

Description

The BuddyPress Docs WordPress plugin before 2.2.5 lacks proper access controls and allows a logged in user to view and download files belonging to another user